Research Article

Challenging the Adversarial Robustness of DNNs Based on Error-Correcting Output Codes

Table 3

Results of the attack against ECOC for MNIST classification.

ParametersProposed (ECOC)C&W (ECOC)C&W (one-hot)
ASR (%)PSNRASR (%)PSNRASR (%)PSNR

(1e − 3, 10, 100, 0)29.321.262621.191.532.48
(1e − 3, 10, 200, 0)43.621.4935.620.73827.69
(1e − 3, 10, 500, 0)55.621.9143.620.3740.524.29
(1e − 3, 10, 1000, 0)64.622.234920.5666.524.97
(1e − 1, 10, 2000, 0)72.322.3557.620.357825.29

Reported parameters indicate, respectively (start point, number of steps of binary search, max iterations, confidence).